{"id":2945,"date":"2015-09-03T07:27:58","date_gmt":"2015-09-03T06:27:58","guid":{"rendered":"https:\/\/www.uk-cheapest.co.uk\/support\/?p=2945"},"modified":"2015-09-03T07:56:21","modified_gmt":"2015-09-03T06:56:21","slug":"protect-against-wordpress-pingback-vulnerability","status":"publish","type":"post","link":"https:\/\/www.uk-cheapest.co.uk\/support\/protect-against-wordpress-pingback-vulnerability\/","title":{"rendered":"Protect against WordPress Pingback Vulnerability"},"content":{"rendered":"<h2>How to Neutralise a\u00a0Pingback DDOS Attack<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-thumbnail wp-image-1908\" src=\"https:\/\/www.uk-cheapest.co.uk\/support\/wp-content\/uploads\/2015\/04\/ssh-150x150.png\" alt=\"ssh\" width=\"150\" height=\"150\" srcset=\"https:\/\/www.uk-cheapest.co.uk\/support\/wp-content\/uploads\/2015\/04\/ssh-150x150.png 150w, https:\/\/www.uk-cheapest.co.uk\/support\/wp-content\/uploads\/2015\/04\/ssh.png 256w\" sizes=\"(max-width: 150px) 100vw, 150px\" \/>The WordPress Pingback Vulnerability is used to maliciously attack your WordPress site via the Pingback service.<\/p>\n<p>If the attack is heavy enough then not only will your site be seriously slowed if not inaccessible) but your server will also be overloaded with requests thus risking your shared hosting account altogether.<\/p>\n<p>This type of attack is usually instigated via a botnet of many hundreds (if not thousands) of different IP addresses so a simply blocking the IP address of the attacker is not practical.<\/p>\n<p>If you are under attack right now then there are actions you can take to minimise (if not nullify) the effect of attack.<\/p>\n<h2>Disable the WordPress XMLRPC Service<\/h2>\n<p>We can do this by adding a &#8220;deny&#8221; to &#8220;xmlrpc.php&#8221; in your .htaccess file. This will disable the your WordPress site from participating\u00a0with the\u00a0pingback requests.<\/p>\n<p>Add the following to the top of your .htaccess file:<\/p>\n<pre>&lt;files xmlrpc.php&gt;\r\norder deny, allow\r\ndeny from all\r\n&lt;\/files&gt;<\/pre>\n<p>The attack will now have less effect on your server load.<\/p>\n<p>Once the attack is over, you may remove deny code if you need XMLRPC services active on your WordPress site. There&#8217;s a 95% chance you can leave it there with no noticeable\u00a0effect at all.<\/p>\n<h2>Blocking the DDOS\u00a0Attack using CSF<\/h2>\n<p>If you use CSF, you may still want to block the IP addresses of the attacking botnet. It&#8217;s quite easy to do.<\/p>\n<p>Here is a bash one-liner that will do the job for you in real-time:<\/p>\n<pre>tail -f \/var\/www\/vhosts\/yourdomain.com\/logs\/access_log | grep \"\\\"WordPress\/\" | grep -v \"POST \" | awk '{print $1}' | while read IP; do \/usr\/sbin\/csf -td $IP 7d BlockPingback; done<\/pre>\n<p>There is some satisfaction in\u00a0having the IPs permanently blocked.\u00a0You can add the resulting IP block to your deny files on all servers and accounts.<\/p>\n<p>It does make sense as all the attacking WordPress sites are clearly compromised and will no longer be a problem (for you at least) if permanently blocked from your server.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>How to Neutralise a\u00a0Pingback DDOS Attack The WordPress Pingback Vulnerability is used to maliciously attack your WordPress site via the Pingback service. If the attack is heavy enough then not only will your site be seriously slowed if not inaccessible) but your server will also be overloaded with requests thus risking your shared hosting account &#8230; <a title=\"Protect against WordPress Pingback Vulnerability\" class=\"read-more\" href=\"https:\/\/www.uk-cheapest.co.uk\/support\/protect-against-wordpress-pingback-vulnerability\/\" aria-label=\"More on Protect against WordPress Pingback Vulnerability\">Read more&#8230;<\/a><\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"generate_page_header":"","footnotes":""},"categories":[166,64],"tags":[],"class_list":["post-2945","post","type-post","status-publish","format-standard","hentry","category-dedicated-servers","category-wordpress-support"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v23.4 (Yoast SEO v23.4) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Protect against WordPress Pingback Vulnerability - UK-Cheapest.co.uk<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.uk-cheapest.co.uk\/support\/protect-against-wordpress-pingback-vulnerability\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Protect against WordPress Pingback Vulnerability\" \/>\n<meta property=\"og:description\" content=\"How to Neutralise a\u00a0Pingback DDOS Attack The WordPress Pingback Vulnerability is used to maliciously attack your WordPress site via the Pingback service. If the attack is heavy enough then not only will your site be seriously slowed if not inaccessible) but your server will also be overloaded with requests thus risking your shared hosting account ... Read more...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.uk-cheapest.co.uk\/support\/protect-against-wordpress-pingback-vulnerability\/\" \/>\n<meta property=\"og:site_name\" content=\"UK-Cheapest.co.uk\" \/>\n<meta property=\"article:published_time\" content=\"2015-09-03T06:27:58+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2015-09-03T06:56:21+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.uk-cheapest.co.uk\/support\/wp-content\/uploads\/2015\/04\/ssh-150x150.png\" \/>\n<meta name=\"author\" content=\"UKC\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@ukchelpdesk\" \/>\n<meta name=\"twitter:site\" content=\"@ukchelpdesk\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"UKC\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.uk-cheapest.co.uk\/support\/protect-against-wordpress-pingback-vulnerability\/\",\"url\":\"https:\/\/www.uk-cheapest.co.uk\/support\/protect-against-wordpress-pingback-vulnerability\/\",\"name\":\"Protect against WordPress Pingback Vulnerability - UK-Cheapest.co.uk\",\"isPartOf\":{\"@id\":\"https:\/\/www.uk-cheapest.co.uk\/support\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.uk-cheapest.co.uk\/support\/protect-against-wordpress-pingback-vulnerability\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.uk-cheapest.co.uk\/support\/protect-against-wordpress-pingback-vulnerability\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.uk-cheapest.co.uk\/support\/wp-content\/uploads\/2015\/04\/ssh-150x150.png\",\"breadcrumb\":{\"@id\":\"https:\/\/www.uk-cheapest.co.uk\/support\/protect-against-wordpress-pingback-vulnerability\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.uk-cheapest.co.uk\/support\/protect-against-wordpress-pingback-vulnerability\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.uk-cheapest.co.uk\/support\/protect-against-wordpress-pingback-vulnerability\/#primaryimage\",\"url\":\"https:\/\/www.uk-cheapest.co.uk\/support\/wp-content\/uploads\/2015\/04\/ssh.png\",\"contentUrl\":\"https:\/\/www.uk-cheapest.co.uk\/support\/wp-content\/uploads\/2015\/04\/ssh.png\",\"width\":256,\"height\":256},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.uk-cheapest.co.uk\/support\/protect-against-wordpress-pingback-vulnerability\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"UK-Cheapest.co.uk\",\"item\":\"https:\/\/www.uk-cheapest.co.uk\/support\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Protect against WordPress Pingback Vulnerability\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.uk-cheapest.co.uk\/support\/#website\",\"url\":\"https:\/\/www.uk-cheapest.co.uk\/support\/\",\"name\":\"UK-Cheapest.co.uk\",\"description\":\"Cheap Domain Names, Web Hosting, Site Builder &amp; Web Security\",\"publisher\":{\"@id\":\"https:\/\/www.uk-cheapest.co.uk\/support\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.uk-cheapest.co.uk\/support\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.uk-cheapest.co.uk\/support\/#organization\",\"name\":\"UKC\",\"url\":\"https:\/\/www.uk-cheapest.co.uk\/support\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.uk-cheapest.co.uk\/support\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.uk-cheapest.co.uk\/support\/wp-content\/uploads\/2023\/12\/Screenshot-2023-12-14-at-17.40.07.png\",\"contentUrl\":\"https:\/\/www.uk-cheapest.co.uk\/support\/wp-content\/uploads\/2023\/12\/Screenshot-2023-12-14-at-17.40.07.png\",\"width\":217,\"height\":55,\"caption\":\"UKC\"},\"image\":{\"@id\":\"https:\/\/www.uk-cheapest.co.uk\/support\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/x.com\/ukchelpdesk\",\"https:\/\/www.instagram.com\/ukc_hosting\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.uk-cheapest.co.uk\/support\/#\/schema\/person\/135cf981b8a3a120603fcbc027eed746\",\"name\":\"UKC\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.uk-cheapest.co.uk\/support\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/f39b95f178ec21ebe3134a71baa1146d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/f39b95f178ec21ebe3134a71baa1146d?s=96&d=mm&r=g\",\"caption\":\"UKC\"},\"sameAs\":[\"https:\/\/www.uk-cheapest.co.uk\"],\"url\":\"https:\/\/www.uk-cheapest.co.uk\/support\/author\/colin\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Protect against WordPress Pingback Vulnerability - UK-Cheapest.co.uk","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.uk-cheapest.co.uk\/support\/protect-against-wordpress-pingback-vulnerability\/","og_locale":"en_GB","og_type":"article","og_title":"Protect against WordPress Pingback Vulnerability","og_description":"How to Neutralise a\u00a0Pingback DDOS Attack The WordPress Pingback Vulnerability is used to maliciously attack your WordPress site via the Pingback service. If the attack is heavy enough then not only will your site be seriously slowed if not inaccessible) but your server will also be overloaded with requests thus risking your shared hosting account ... Read more...","og_url":"https:\/\/www.uk-cheapest.co.uk\/support\/protect-against-wordpress-pingback-vulnerability\/","og_site_name":"UK-Cheapest.co.uk","article_published_time":"2015-09-03T06:27:58+00:00","article_modified_time":"2015-09-03T06:56:21+00:00","og_image":[{"url":"https:\/\/www.uk-cheapest.co.uk\/support\/wp-content\/uploads\/2015\/04\/ssh-150x150.png"}],"author":"UKC","twitter_card":"summary_large_image","twitter_creator":"@ukchelpdesk","twitter_site":"@ukchelpdesk","twitter_misc":{"Written by":"UKC","Estimated reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.uk-cheapest.co.uk\/support\/protect-against-wordpress-pingback-vulnerability\/","url":"https:\/\/www.uk-cheapest.co.uk\/support\/protect-against-wordpress-pingback-vulnerability\/","name":"Protect against WordPress Pingback Vulnerability - UK-Cheapest.co.uk","isPartOf":{"@id":"https:\/\/www.uk-cheapest.co.uk\/support\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.uk-cheapest.co.uk\/support\/protect-against-wordpress-pingback-vulnerability\/#primaryimage"},"image":{"@id":"https:\/\/www.uk-cheapest.co.uk\/support\/protect-against-wordpress-pingback-vulnerability\/#primaryimage"},"thumbnailUrl":"https:\/\/www.uk-cheapest.co.uk\/support\/wp-content\/uploads\/2015\/04\/ssh-150x150.png","breadcrumb":{"@id":"https:\/\/www.uk-cheapest.co.uk\/support\/protect-against-wordpress-pingback-vulnerability\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.uk-cheapest.co.uk\/support\/protect-against-wordpress-pingback-vulnerability\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.uk-cheapest.co.uk\/support\/protect-against-wordpress-pingback-vulnerability\/#primaryimage","url":"https:\/\/www.uk-cheapest.co.uk\/support\/wp-content\/uploads\/2015\/04\/ssh.png","contentUrl":"https:\/\/www.uk-cheapest.co.uk\/support\/wp-content\/uploads\/2015\/04\/ssh.png","width":256,"height":256},{"@type":"BreadcrumbList","@id":"https:\/\/www.uk-cheapest.co.uk\/support\/protect-against-wordpress-pingback-vulnerability\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"UK-Cheapest.co.uk","item":"https:\/\/www.uk-cheapest.co.uk\/support\/"},{"@type":"ListItem","position":2,"name":"Protect against WordPress Pingback Vulnerability"}]},{"@type":"WebSite","@id":"https:\/\/www.uk-cheapest.co.uk\/support\/#website","url":"https:\/\/www.uk-cheapest.co.uk\/support\/","name":"UK-Cheapest.co.uk","description":"Cheap Domain Names, Web Hosting, Site Builder &amp; Web Security","publisher":{"@id":"https:\/\/www.uk-cheapest.co.uk\/support\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.uk-cheapest.co.uk\/support\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/www.uk-cheapest.co.uk\/support\/#organization","name":"UKC","url":"https:\/\/www.uk-cheapest.co.uk\/support\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.uk-cheapest.co.uk\/support\/#\/schema\/logo\/image\/","url":"https:\/\/www.uk-cheapest.co.uk\/support\/wp-content\/uploads\/2023\/12\/Screenshot-2023-12-14-at-17.40.07.png","contentUrl":"https:\/\/www.uk-cheapest.co.uk\/support\/wp-content\/uploads\/2023\/12\/Screenshot-2023-12-14-at-17.40.07.png","width":217,"height":55,"caption":"UKC"},"image":{"@id":"https:\/\/www.uk-cheapest.co.uk\/support\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/ukchelpdesk","https:\/\/www.instagram.com\/ukc_hosting\/"]},{"@type":"Person","@id":"https:\/\/www.uk-cheapest.co.uk\/support\/#\/schema\/person\/135cf981b8a3a120603fcbc027eed746","name":"UKC","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.uk-cheapest.co.uk\/support\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/f39b95f178ec21ebe3134a71baa1146d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f39b95f178ec21ebe3134a71baa1146d?s=96&d=mm&r=g","caption":"UKC"},"sameAs":["https:\/\/www.uk-cheapest.co.uk"],"url":"https:\/\/www.uk-cheapest.co.uk\/support\/author\/colin\/"}]}},"_links":{"self":[{"href":"https:\/\/www.uk-cheapest.co.uk\/support\/wp-json\/wp\/v2\/posts\/2945"}],"collection":[{"href":"https:\/\/www.uk-cheapest.co.uk\/support\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.uk-cheapest.co.uk\/support\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.uk-cheapest.co.uk\/support\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.uk-cheapest.co.uk\/support\/wp-json\/wp\/v2\/comments?post=2945"}],"version-history":[{"count":8,"href":"https:\/\/www.uk-cheapest.co.uk\/support\/wp-json\/wp\/v2\/posts\/2945\/revisions"}],"predecessor-version":[{"id":2953,"href":"https:\/\/www.uk-cheapest.co.uk\/support\/wp-json\/wp\/v2\/posts\/2945\/revisions\/2953"}],"wp:attachment":[{"href":"https:\/\/www.uk-cheapest.co.uk\/support\/wp-json\/wp\/v2\/media?parent=2945"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.uk-cheapest.co.uk\/support\/wp-json\/wp\/v2\/categories?post=2945"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.uk-cheapest.co.uk\/support\/wp-json\/wp\/v2\/tags?post=2945"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}